A malicious npm package named "indexedbtree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexedbtree is a malicious npm package mimicking the legit sortedbtree package, an ordinary Btreeindexing utility," Checkmarx said. ".π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity